CVE-2024-47876
Severity CVSS v4.0:
HIGH
Type:
CWE-285
Improper Authorization
Publication date:
15/10/2024
Last modified:
30/10/2025
Description
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sakailms:sakai:*:*:*:*:*:*:*:* | 23.0 (including) | 23.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



